Anonymous Charger Authentication for Offline Private Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic authentication methods for devices lack effective mechanisms to securely verify the authenticity of chargers and devices without relying on network connections, leading to potential exposure to counterfeit or compromised devices, and fail to maintain user privacy and security.
Innovation Solution
A method for anonymous authentication between electronic devices and chargers that uses direct communication to verify authentication keys without uniquely identifying information, allowing for revocation of compromised credentials without affecting genuine devices, and operates independently of network connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional electronic authentication methods are used, then devices can be authenticated, but user privacy is compromised and network connections are required
Solution Approach 1:
The patent extracts the authentication process from network-dependent systems and implements it as a standalone direct device-to-device protocol. The authentication keys and verification processes are removed from network infrastructure and embedded directly in the charging cable and device, eliminating the need for network connections while preserving authentication security.
Solution Approach 2:
The patent introduces authentication keys as intermediary elements that enable verification without exposing user identity. These keys act as mediators between the charging cable and device, allowing mutual authentication while preventing either party from learning about the other's unique identifier, thus protecting user privacy.
2Measurement precision
If unique identifiers are used for authentication, then devices can be uniquely identified, but user anonymity is lost
Solution Approach 1:
The patent implements asymmetric authentication where the charging cable and device have different roles and capabilities. The cable can verify device authenticity through authentication keys, but neither party can determine the other's unique identifier. This asymmetric design maintains authentication accuracy while preserving mutual anonymity.
Solution Approach 2:
The patent uses authentication keys that are distributed copies of verification credentials rather than unique identifiers. Multiple devices can share the same authentication keys, allowing accurate verification of authenticity without enabling identification of individual devices, thus preserving anonymity.
3Reliability
If credentials are revoked for compromised devices, then security is improved, but all devices of the same model may be affected
Solution Approach 1:
The patent segments authentication credentials into model-specific groups rather than using universal credentials. When a device is compromised, only the authentication keys associated with that specific device instance or small group are revoked, not all keys for the entire device model. This segmentation allows selective revocation that maintains security while preserving charging availability for uncompromised devices.
4Extent of automation
If network connections are required for authentication, then centralized control is possible, but authentication cannot work offline
Solution Approach 1:
The patent implements preliminary action by pre-loading authentication keys into devices and charging cables during manufacturing. This preliminary configuration enables offline authentication capability without requiring network connections during the charging process. Centralized management is achieved through the initial key distribution, while offline versatility is maintained through local storage and verification of these pre-configured keys.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Methods, systems, apparatus, and computer-readable storage devices for anonymous device authentication. A method includes: accessing, by the electronic device, data stored by the electronic device that identifies authentication keys the electronic device accepts as valid; sending, by the electronic device to a second electronic device, an authentication request that identifies a set of authentication keys including at least some of authentication keys the electronic device accepts as valid; and receiving, by the electronic device, response data that the second electronic device provides in response to the authentication request. The response data (i) identifies a particular authentication key from the set of authentication keys identified by the authentication request, and (ii) includes a signature generated using the particular authentication key. The method includes authenticating, by the electronic device, the second electronic device by determining that the received signature was generated using the particular authentication key.